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Foreword 



rd , 



This Technical Specification (TS) has been produced by the 3 Generation Partnership Project (3GPP). 

The contents of the present document are subject to continuing work within the TSG and may change following formal 
TSG approval. Should the TSG modify the contents of the present document, it will be re-released by the TSG with an 
identifying change of release date and an increase in version number as follows: 

Version x.y.z 

where: 

X the first digit: 

1 presented to TSG for information; 

2 presented to TSG for approval; 

3 or greater indicates TSG approved document under change control. 

y the second digit is incremented for all changes of substance, i.e. technical enhancements, corrections, 
updates, etc. 

z the third digit is incremented when editorial only changes have been incorporated in the document. 



Introduction 



This document has been prepared by the 3GPP Task Force, and contains an example set of algorithms which may be 
used as the authentication and key generation f mictions f 1, f 1 *, f2,f 3, f 4, f 5 and/5*. (It is not mandatory that the 
particular algorithms specified in this document are used — all seven functions are operator-specifiable rather than 
being fully standardised). This document is one five, which between them form the entire specification of the example 
algorithms, entitled: 

3GPP TS 35.205: "3rd Generation Partnership Project; Technical Specification Group Services and System 
Aspects; 3G Security; Specification of the MILENAGE Algorithm Set: An example algorithm set for the 3GPP 
authentication and key generation functions fl, fl*, f2, f3, f4, f5 and f5*; 
Document 1: General". 

3GPP TS 35.206: "3rd Generation Partnership Project; Technical Specification Group Services and System 
Aspects; 3G Security; Specification of the MILENAGE Algorithm Set: An example algorithm set for the 3GPP 
authentication and key generation functions fl, fl*, f2, f3, f4, f5 and f5*; 
Document 2: Algorithm Specification". 

3GPP TS 35.207: "3rd Generation Partnership Project; Technical Specification Group Services and System 
Aspects; 3G Security; Specification of the MILENAGE Algorithm Set: An example algorithm set for the 3GPP 
authentication and key generation functions fl, fl*, f2, f3, f4, f5 and f5*; 
Document 3: Implementors' Test Data". 

3GPP TS 35.208: "3rd Generation Partnership Project; Technical Specification Group Services and System 
Aspects; 3G Security; Specification of the MILENAGE Algorithm Set: An example algorithm set for the 3GPP 
authentication and key generation functions fl, fl*, f2, f3, f4, f5 and f5*; 
Document 4: Design Conformance Test Data". 

3GPP TR 35.909: "3rd Generation Partnership Project; Technical Specification Group Services and System 
Aspects; 3G Security; Specification of the MILENAGE Algorithm Set: An example algorithm set for the 3GPP 
authentication and key generation functions fl, fl*, f2, f3, f4, f5 and f5*; 
Document 5: Summary and results of design and evaluation". 
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1 Outline of the implementors' test data 

Section 2 introduces the algorithms and describes the notation used in the subsequent sections. 

Section 3 provides test data for the Rijndael kernel function. 

Section 4 provides test data for the authentication algorithms// and//*. 

Section 5 provides test data for the algorithms y2, /5 and/3. 

Section 6 provides test data for the algorithms/^ and/5*. 

1.1 References 

The following documents contain provisions which, through reference in this text, constitute provisions of the present 
document. 

• References are either specific (identified by date of publication, edition number, version number, etc.) or 
non-specific. 

• For a specific reference, subsequent revisions do not apply. 

• For a non-specific reference, the latest version applies. In the case of a reference to a 3GPP document (including 
a GSM document), a non-specific reference implicitly refers to the latest version of that document in the same 
Release as the present document. 

[1] 3GPP TS 33.102 v3.5.0: "3rd Generation Partnership Project; Technical Specification Group 

Services and System Aspects; 3G Security; Security Architecture". 

[2] 3GPP TS 33.105 v3.4.0: "3rd Generation Partnership Project; Technical Specification Group 

Services and System Aspects; 3G Security; Cryptographic Algorithm Requirements". 

[3] 3GPP TS 35.206: "3rd Generation Partnership Project; Technical Specification Group Services 

and System Aspects; 3G Security; Specification of the MILENAGE Algorithm Set: An example 
algorithm set for the 3GPP authentication and key generation functions fl, fl*, f2, G, f4, f5 and 
f5*; Document 2: Algorithm Specification". 

[4] 3GPP TS 35.207: "3rd Generation Partnership Project; Technical Specification Group Services 

and System Aspects; 3G Security; Specification of the MILENAGE Algorithm Set: An example 
algorithm set for the 3GPP authentication and key generation functions fl, fl*, f2, O, f4, f5 and 
f5*; Document 3: Implementors' Test Data" (this document). 

[5] 3GPP TS 35.208: "3rd Generation Partnership Project; Technical Specification Group Services 

and System Aspects; 3G Security; Specification of the MILENAGE Algorithm Set: An example 
algorithm set for the 3GPP authentication and key generation functions fl, fl*, f2, G, f4, f5 and 
f5*; Document 4: Design Conformance Test Data". 

[6] Joan Daemen and Vincent Rijmen: "AES Proposal: Rijndael", available at 

http://csrc.nist.gov/encryption/aes/round2/AESAlgs/Rijndael/Rijndael.pdfor 
http://www.esat.kuleuven.ac.be/~rijmen/rijndael/rijndaeldocV2.zip 

[7] http://csrc.nist.gov/encryption/aes/ 
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2.1 



Introductory information 



Introduction 



Within the security architecture of the 3GPP system there are seven security f unctions f 1, f 1 *, f2,f 3, f 4, f 5 and/5*. 
The operation of these functions falls within the domain of one operator, and the functions are therefore to be specified 
by each operator rather than being fully standardized. The algorithms specified in this document are examples that may 
be used by an operator who does not wish to design his own. 

The inputs and outputs of all seven algorithms are defined in section 2.5. 

2.2 Radix 

Unless stated otherwise, all test data values presented in this document are in hexadecimal. 



2.3 Bit/Byte ordering 



All data variables in this specification are presented with the most significant bit (or byte) on the left hand side and the 
least significant bit (or byte) on the right hand side. Where a variable is broken down into a number of substrings, the 
leftmost (most significant) substring is numbered 0, the next most significant is numbered 1, and so on through to the 
least significant. 



2.4 List of Variables 



AK 

AMF 

cl,c2,c3,c4,c5 

CK 

IK 

K 

MAC-A 

MAC-S 

OP 

OPc 

rl,r2,r3,r4,r5 

RAND 

RES 

SQN 



a 48-bit anonymity key that is the output of either of the functions /5 and/5*. 

a 16-bit authentication management field that is an input to the functions/7 and/Z*. 

128-bit constants, which are XORed onto intermediate variables. 

a 128-bit confidentiality key that is the output of the function/?. 

a 128-bit integrity key that is the output of the function/4. 

a 128-bit subscriber key that is an input to the f unctions f 1, f 1 *,f2,f3,f 4, f 5 and/5*. 

a 64-bit network authentication code that is the output of the function//. 

a 64-bit resynchronisation authentication code that is the output of the function//*. 

a 128-bit Operator Variant Algorithm Configuration Field that is a component of the functions//, 
/7*,i2,/?,/4,/5 and/5* 

a 128-bit value derived from OP and K and used within the computation of the functions. 

integers in the range 0-127 inclusive, which define amounts by which intermediate variables are 
cyclically rotated. 

a 128-bit random challenge that is an input to the functions f 1, fl*,f2,f3,f 4, f 5 and/5*. 

a 64-bit signed response that is the output of the function _/2. 

a 48-bit sequence number that is an input to either of the functions// and//*. (For//* this input 
is more precisely called SQNms-) 
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2.5 Algorithm Inputs and Outputs 

The inputs to the algorithms are given in tables 1 and 2, the outputs in tables 3-9 below. 

Table 1. inputs to f1 and f1* 



Parameter 


Size (bits) 


Comment 


K 


128 


Subscriber key K[0]...K[127] 


RAND 


128 


Random challenge RAND[0]...RAND[127] 


SQN 


48 


Sequence number SQN[0]...SQN[47]. (For fr*this input is 
more precisely called SQNms-) 


AMF 


16 


Authentication management field AMF[0]...AI\/IF[15] 


Table 2. inputs to f2, f3, f4, f5 and f5* 


Parameter 


Size (bits) 


Comment .^^^^hwI 


K 


128 


Subscriber key K[0]...K[127] 


RAND 


128 


Random challenge RAND[0]...RAND[127] 


Table 3. f1 output 


Parameter 


Size (bits) 


Comment 


MAC-A 


64 


Network authentication code IVIAC-A[0]...MAC-A[63] 


Table 4. ^r output 


Parameter 


Size (bits) 


Comment 


MAC-S 


64 


Resynch authentication code MAC-S[0]...MAC-S[63] 


Tables. /2 output 


Parameter 


Size (bits) 


Comment 


RES 


64 


Response RES[0]...RES[63] 


Table 6. f3 output 


Parameter 


Size (bits) 


Comment 


CK 


128 


Confidentiality key CK[01...CK[1271 


Table 7. f4 output 


Parameter 


Size (bits) 


Comment 


IK 


128 


Integrity key IKf01...IK[1271 


Tables. f5 output 


Parameter 


Size (bits) 


Comment 


AK 


48 


Anonymity key AK[0]...AK[47] 


Tables. ^5* output 


Parameter 


Size (bits) 


Comment 


AK 


48 


Resynch anonymity key AK[0]...AK[47] 



NOTE: Both f5 and f5* outputs are called AK according to reference [2]. In practice only one of them will be 
calculated in each instance of the authentication and key agreement procedure. 
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2.6 Coverage 



The test data sets for the kernel function Rijndael have been chosen in a way that, provided all data sets are tested: 

Every S-Box entry is being used. 

Each input bit has been in both the '0' and '1' state. 

The test data sets for all seven functions are based on the test data sets above. The values for OP, K and RAND have 
been chosen such that the input values of the first encryption are the test data sets of Rijndael. This way, the following 
coverage is being reached, provided all test data sets are tested: 

The conditions for Rijndael seen above. 

Each input bit for the functions has been in both the '0' and '1' state. 



Rijndael test data 



3.1 



Overview 



The test data sets presented here are for the cryptographic kernel function Rijndael with 128-bit key and data as it is 
specified in [3]. 



3.2 



Format 



Rijndael is composed of 10 rounds that transform the input into the output. An intermediate result is called the State. 
The State can be pictured as a 4x4 rectangular array of bytes (128 bits in total). The cipher key is similarly pictured as a 
4x4 rectangular array. In each of the data intermediate values of the round key array and of the State are given. For the 
first set the value of the State after each step of the algorithm is given. In the remaining data sets only the value of the 
State as it is at the end of each round is given. 

The internal states will be written as hexadecimal strings, column by column and from top to bottom within each 
column (the same way as plaintext bytes are fed into the matrix). 



Example: 



The State 



C2 


37 


2E 


21 


3C 


69 


51 


9E 


62 


EC 


9D 


23 


CC 


29 


D8 


F7 



is represented by the string c23c62cc 3769ec29 2e519dd8 219e23f7. 
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3.3 



Test Set 1 



0: 
1: 
2: 
3: 

4 : 

5 : 
6: 
7: 
8: 
9: 



Key: 465b5ce8 
Plaintext : ee 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 10 : 
add keys { ) : 
Substitution { 
Row shift (1) : 
mix column (1) 
add keys { 1 ) : 
Substitution { 
Row shift (2) : 
mix column (2) 
add keys (2) : 
Substitution { 
Row shift (3) : 
mix column (3) 
add keys { 3 ) : 
Substitution { 
Row shift (4) : 
mix column (4) 
add keys (4) : 
Substitution { 
Row shift (5) : 
mix column (5) 
add keys { 5 ) : 
Substitution { 
Row shift (6) : 
mix column (6) 
add keys { 6 ) : 
Substitution { 
Row shift (7) : 
mix column (7) 
add keys { 7 ) : 
Substitution { 
Row shift (8) : 
mix column (8) 
add keys { 8 ) : 
Substitution { 
Row shift (9) : 
mix column (9) 
add keys { 9 ) : 
Substitution { 
Row shift (10) 
add keys (10) : 
Ciphertext : 



bl99b49f aa5fOa2e e238a6bc 
6f7cf 037d37d3 692f7f03 99e7949a 
465b5ce8 bl99b49f aa5f0a2e e238a6bc 
407f3970 fle68def 5bb987cl b981217d 
4e82c626 bfS44bc9 e4ddcc08 5d5ced75 
00d75b6a bfb310a3 5b6edcab 063231de 
2bl04605 94a356a6 cfcd8a0d c9ffbbd3 
2dfa20d8 b959767e 7694fc73 bf6b47aO 
725acOdO cb03b6ae bd974add 02fcOd7d 
828d3fa7 498e8909 f419c3d4 f6e5cea9 
db06ece5 928865ec 6691a638 90746891 
52436d85 cOcb0869 a65aae51 362ec6c0 
55f7d780 953cdfe9 336671b8 0548b778 

a86dab27 b2e4834c c370752d 7bdf3226 

1) : c23c62cc 3769ec29 2e519dd8 219e23f7 

c2699df7 375123CC 2e9e6229 213cecd8 

: 4e5b885c 723c6fa8 ae8S0fdc 32aeadl8 

Oe24bl2c 83dae247 f53f881d 8b2f8c65 

2) : ab36c871 ec5798a0 e675c4a4 3dl5644d 

ab57c44d ec756471 e615c8a0 3d3698a4 

: 3dlfb8ef 49dbc2dc 802f83b7 Ic46d7ba 

739d7ec9 f6bf8915 64f24fbf 411a3acf 

3) : 8f5ef3dd 4208a759 43898408 83a2808a 

8f08848a 428980dd 43a2f359 835ea708 

: 13821109 590dac6e dl4bf726 50c59077 

13554a63 eSbebccd 8a252b8d 56f7ala9 

4) : 7dfcd6fb 8eae65bd 7e3ffl5d bl6832d3 

7daefld3 8e3f32fb 7e68d6bd blfc655d 

: 31el4465 8f5dc369 2f727d5d 5ea060eb 

lafl0260 lbfe95cf eObff750 975fdb38 

5) : a2al77dO afbb2a8a el08S853 88cfb907 

a2bb6807 af08b9d0 elcf778a 88al2a53 

: e670c020 34bfa5e0 6e77458f 8afc88ae 

Cb8ae0f8 8de6d39e 18e3b9fc 3597cfOe 

6) : If7eel41 5d8e660b adll56bO 96888aab 

If8e56ab 5dll8a41 ad88el0b 967e66b0 

: 4a49dbb4 42bb80fe 2895el93 6370efc2 

38131bS4 89b83650 9502ab4e 618ce2bf 

7) : 077daf43 a76c0553 2a77622f ef649808 

07SCS208 a7779843 2a64af53 ef7d052f 

: d071b717 17b93e9b 045bfel3 6835e90c 

52fc88bO 5e37b792 f0423dc7 9ed027a5 

8) : 00b0c4e7 589aa94f 8c2c27cS 0b70cc06 

009a2706 582ccce7 8c70c44f 0bb0a9c6 

: 9440debl efa8c5dd 1874bea5 b256a393 

4f463254 7d20a031 7ee5189d 2222cb02 

9) : 845a2320 ffb7eOc7 f3d9ad5e 93931f77 

84b7ad77 ffd91f20 f39323c7 935ae05e 

: 0b6aeb63 aa57789c b76c742b 6d42f0a8 

592986e6 6a9c70f5 1136da7a 5b6c3668 

10) :cba5448e 02de51e6 820557da 39500545 

: cbde5745 0205058e 825044e6 39a551da 

9e2980c5 9739da67 bl36355e 3cede6a2 

9e2980c5 9739da67 bl36355e 3cede6a2 
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3.4. 



Test Set 2 



Key: 0396eb3 



Plaintext 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
End of 
End of 
End of 
End of 
End of 
End of 
End of 
End of 
End of 
End of 



9 
10 
Round 
round 
round 
round 
round 
round 
round 
round 
round 
round 



1 7b6dlc36 fl9clc84 cd6ffdl6 
3CC3640 C5d6a521 d81235bd 0882bf0a 
0396eb31 7b6dlc36 fl9clc84 cd6ffdl6 
aac2ac8c dlafbOba 2033ac3e ed5c5128 
e21398d9 33bc2863 138f845d fed3d575 
80100562 b3ac2d01 a023a95c 5ef07c29 
0400a03a b7ac8d3b 178f2467 497f584e 
C66a8f01 71c6023a 6649265d 2f367el3 
e399f214 925ff02e f416d673 db20a860 
145b22ad 8604d283 721204fO a932ac90 
b7ca427e 31ce90fd 43dc940d eaee389d 
84cdlcf9 b5038c04 f6dfl809 lc312094 
757a3e65 c079b261 36a6aa68 2a978afc 



Ciphertext : 



0: 905add71 bebbb917 298e2939 c5ed421c 

1: 7605C840 32e4al3b bf94cea5 2775d315 

2: fb262fcl 7c78fe50 b567e7ef f4991cSf 

3: 7d736610 e36al3d8 7e5d4d65 5db3231a 

4: a6677d9e ad85d9ed Of927ff5 6bfcb6f2 

5: 779f0321 d4145989 eb0bfa22 96eldff5 

6: CC129610 Ic05a8a2 f23ec385 cec8c0e6 

7: 9f3ad732 18f8d6bb f2cll07c blfad328 

8: 27e20beb bdlaec49 d9f 70961 Ic2cb788 

9: 3f992786 b9a0f782 If4e477a ad2089b8 
009a9e09 96561525 f611667b bf79e226 



3.5. 



Test Set 3 



Key: fec86ba6 eb707edO 8905757b Ibb44b8f 

E7a8f0d 108b7f2d 97a53eac Cld958d9 
fec86ba6 eb707edO 8905757b Ibb44b8f 
727bl809 990b66d9 100el3a2 Obba582d 



Plaintext 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
End of 
End of 
End of 
End of 
End of 
End of 
End of 
End of 
End of 
End of 
Ciphertext : 





1 

2 

3 

4 

5 

6 

7 

8 

9 

10 

Round 

round 

round 

round 

round 

round 

round 

round 

round 

round 



8411C022 ldlaa6fb Odl4b559 06aeed74 
6444524d 795ef4b6 744a41ef 72e4ac9b 
05d5460d 7c8bb2bb 08clf354 7a255fcf 
2alaccd7 56917e6c 5e508d38 2475d2f7 
97afa4el Cl3eda8d 9f6e57b5 bblb8542 
7838880b b9065286 26680533 9d738071 
77f52b55 cef379d3 e89b7ceO 75e8fc91 
f745aac8 39b6d31b dl2daffb a4c5536a 
67a8a881 5ele7b9a 8f33d461 2bf6870b 
0: 71b2e4ab fbfbOlfd Iea04bd7 da6dl356 
1: 3cb90132 a33ad591 8deb73c9 8e09d283 
2: bl8781c8 bf3e51ff 494e89da 10c3d8ab 
3: e763dbdf 9143322b 6a2f76ac 423f31b6 
4: 6e736al4 03ec0ad6 db08e567 8610665a 
5: 21ccedld 3925460d 8696fbd7 c41843c2 
6: ldl81787 f09d9b62 79437634 Oa71746b 
7: 8el78364 1104c2af f5220eee b3714a51 
8: 3224e59e ea6ela8d 5476716c a93953a3 
9: a2b75585 8266b04a 2304d3ea bld71930 
5d9bce85 4decafOd a93d28b7 e35f608c 
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3.6 



Test Set 4 



Key: 9e5944ae 



Plaintext 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
End of 
End of 
End of 
End of 
End of 
End of 
End of 
End of 
End of 
End of 



68 



1 

2 

3 

4 

5 

6 

7 



9 
10 
Round 
round 
round 
round 
round 
round 
round 
round 
round 
round 



a94b8116 5c82fbf9 f32db751 
c98bbf ab628ecl adf2a3d9 0c34a751 
9e5944ae a94b8116 5c82fbf9 f32db751 
47f095a3 eebbl4b5 b239ef4c 4114581d 
bf9a3120 51212595 e318cad9 a20c92c4 
45d52dla 14f4088f f7ecc256 55e05092 
ac8662e6 b8726a69 4f9ea83f Ia7ef8ad 
4fc7f744 f7b59d2d b82b3512 a255cdbf 
937aff7e S4cf6253 dce45741 7ebl9afe 
lbc2448d 7fOd26de a3e9719f dd58eb61 
fl2bab4c 8e268d92 2dcffcOd f097176c 
62dbfbc0 ecfd7652 Cl328a5f 31a59d33 
52853807 be784e55 7f4ac40a 4eef5939 



f690cfll 02290fd7 fl705820 ffl91000 
3e3e036c bba920a8 08a087f6 Ocef0044 
a2b7531f 96e51993 40c28eb2 7dOd6d5c 
12272200 bcaa9ea6 b6a0a2d4 b306ec9b 
e4564fl8 e4eScd2e d584d859 ccc5974d 
96e9eccd el4c4cOO fad9d057 8a7010e3 
b23995ae a7a5fcde d841096f d2d345fd 
2aae8b7b d31al204 fc27054a 82aad44c 
9f0541e3 643ad4fe 768997a8 fecl08c3 
f2b6d9e2 b9aacl22 01df0181 6bd28059 



Ciphertext: db2944cc e8e683cd 03fffl99 31al2135 



3.7 



Test Set 5 



Key: 4abldebO 
Plaintext : a8 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
End of 
End of 
End of 
End of 
End of 
End of 
End of 
End of 
End of 
End of 




1 
2 
3 
4 
5 
6 
7 
8 
9 
10 
Round 
round 
round 
round 
round 
round 
round 
round 
round 
round 



5ca6ceb0 51fc98e7 7d02Sa84 
40bldd 60249aa3 22016b4b 31daf3b8 
4abldebO 5ca6cebO 51fc98e7 7d026a84 
3cb3814f 60154fff 31e9d718 4cebbd9c 
d7c95f66 b7dcl099 8635c781 cade7ald 
cel3fbl2 79cfeb8b fffa2c0a 35245617 
fOa20b84 896de00f 7697cc05 43b39al2 
8dlac29e 04772291 72eOee94 31537486 
40888659 44ffa4c8 361f4a5c 074c3eda 
293adl9c 6dc57554 5bda3f08 5c9601d2 
394664d6 54831182 Of592e8a 53cf2f58 
a8530e3b fcd01fb9 f3893133 a0461e6b 
C42171db 38fl6e62 cb785f51 6b3e413a 



e2fl6f6d 3C825413 73fdf3ac 4cd8993c 
c4fl362f 8343731b 423af5al 576add5f 
e81fc43b 3b66dadd 72bd09b7 3964d3ba 
43195665 ac918275 67d94fOc b4fdcaff 
ce20b983 d6477b7c b7efd855 c846fcbe 
b4c7c29e d5035f3c 93178158 e55176d0 
b097f842 7a443al3 33fe2bla 5a221a77 
d516dOb5 9aa33f60 549a6a7e 9aladl5c 
691db74f 07C70966 12662783 77953444 
c7699fl7 a4df4ed5 9ec7ce96 4b0f6209 



Ciphertext: 02bffada 7137c492 c00e8452 d8c76eaa 



£75/ 



3GPP TS 35.207 version 8.0.0 Release 8 



12 



ETSI TS 135 207 V8.0.0 (2009-02) 



3.8 



Test Set 6 



d6 



1 

2 

3 

4 

5 

6 

7 



Key: Sc38all6 
Plaintext 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
Round key 
End of 
End of 
End of 
End of 
End of 
End of 
End of 
End of 
End of 
End of 



9 
10 
Round 
round 
round 
round 
round 
round 
round 
round 
round 
round 



ac280c45 
6789ef f5 
6c38all6 
275C2507 
86cc03cb 
ebe8b7e3 
Iec38c9b 
fb6al6dc 
ba9455f9 
584d4480 
99ef40a6 
8182c2a8 
629bcOff 



ba5f2 
af 2ac 
4a8f6 
15d8S 
14650 
68028 
49c6b 
e9blf 
1999a 
ef Oa9 



Ciphertext: bdf226fe 



4f59332e e35c8c4f 
996b9c ffd89e0a 77148657 
ac280c45 4f59332e e35c8c4f 
8b742942 c42dla6c 27719623 
0db82a89 c99530e5 eee4a6c6 
e6509d6a 2fc5ad8f Cl210b49 
f89311fl d756bc7e 1677b737 
03f9072d d4afbb53 c2d80c64 
b96d52d4 6dc2e987 aflae5e3 
el201654 8ce2ffd3 23f81a30 
78cf56f2 f42da921 d7d5b311 
f94d945a Od603d7b dab58e6a 
9bd654a5 96b669de 4c03e7b4 
8f9 59bl67d9 b081ad24 94480al8 
41c ec979046 e6079852 9a743063 
863 46779622 255afa56 dl2d3b90 
e9a 92abb035 f40d6e6e 09e3b591 
a94 69b5eb49 88e7961d cfl9b897 
187 03a5d481 7c4a28cl 574cf516 
78a df871147 3698dc8a bOOfdlcl 
7ac 4c0e3069 154b3e58 cd8fd4c8 
956 3dd2f44b 42d34338 9b8570d5 
266 fde4bf7d 97a4f536 63bbl809 
cf9ff996 Ie5c2621 b764efbl 



Authentication algorithms f1 AND f1 



4.1 



Overview 



The test data sets presented here are for the authentication algorithms /7,/7*. No detailed data of the internal states of 
Rijndael are presented here as these are covered in chapter 3. 



4.2 



Format 



Each test starts by showing the various inputs (K, RAND, SQN, AMF) to the functions. This will be followed by the 
configuration field OP. Thereafter a table is shown with various intermediate values described in the left column. The 
value OPc in the second row should not be computed on but off the USIM. In the example code OPc is computed inside 
the functions, so it was included in the table. 



4.3 



Test Set 1 



K: 465b5ce8 bl99b49f aa5fOa2e e238a6bc 

RAND: 23553cbe 9637a89d 218ae64d ae47bf35 

SQN: ff9bb4d0 b607 

AMF: b9b9 

OP: cdc202d5 123e20f6 2b6d676a c72cb318 



SQN,AMF expanded to 128 bits 


ff9bb4d0 b607b9b9 ff9bb4d0 b607b9b9 


OPc 


cd63cb71 954a9f4e 48a5994e 37a02baf 


Value after 1^' encryption 


9e2980c5 9739da67 bl36355e 3cede6a2 


(SQN,AMF) XOR OPc, rotated 


b73e2d9e 81a79216 32f87fal 234d26f7 


Input to 2"" encryption 


2917ad5b 169e4871 83ce4aff Ifa0c055 


Output of 2™ encryption 


87fc31b2 cl9530fd 496a36dO f3485a46 


Value of f1 


4a9ffac3 54dfafb3 


Value of «* 


01cfaf9e c4e871e9 
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4.4 



Test Set 2 



K: 0396eb31 7b6dlc36 fl9clc84 cd6ffdl6 

RAND: c00d6031 03dcee52 C4478119 494202e8 

SQN: fd8eef40 df7d 

AMF: afl7 

OP: ff53bade 17df5d4e 793073ce 9d7579fa 



SQN,AMF expanded to 128 bits 


fd8eef40 df7dafl7 fd8eef40 df7dafl7 


OPc 


53C15671 C60a4b73 Ic55b4a4 41cObde2 


Value after 1^' encryption 


009a9e09 96561525 f611667b bf79e226 


(SQN,AMF) XOR OPc, rotated 


eldb5be4 9ebdl2f5 ae4fb931 1977e464 


Input to 2"" encryption 


el41c5ed 08eb07dO 585edf4a a60e0642 


Output of 2™ encryption 


Oe34e569 Cle813c3 b495a241 5f341eal 


Value of f1 


5df5b318 07e258bO 


Value of «* 


a8c016e5 Ief4a343 



4.5 



Test Set 3 



K: fec86ba6 eb707edO 8905757b Ibb44b8f 

RAND: 9f7c8d02 laccf4db 213ccffO C7f71a6a 

SQN: 9d027759 5ffc 

AMF: 725c 

OP: dbc59adc b6f9a0ef 735477b7 fadf8374 



SQN,AMF expanded to 128 bits 


9d027759 5ffc725c 9d027759 5ffc725c 


OPc 


1006020f Oa478bf6 b699fl5c 062e42b3 


Value after 1^' encryption 


5d9bce85 4decafOd a93d28b7 e35f608c 


(SON.AMF) XOR OPc, rotated 


2b9b8605 59d230ef 8d047556 55bbf9aa 


Input to 2™ encryption 


76004880 143e9fe2 24395del b6e49926 


Output of 2™ encryption 


8cadcle6 91e8f977 2318bafe b52a0197 


Value of f1 


9cabc3e9 9baf7281 


Value of «* 


95814ba2 b3044324 



4.6 



Test Set 4 



K: 9e5944ae a94b8116 5c82fbf9 f32db751 

RAND: ce83dbc5 4ac0274a 157cl7f8 0d017bd6 

SQN: Ob604a81 eca8 

AMF: 9e09 

OP: 223014C5 806694C0 07caleee f57f004f 



SQN,AMF expanded to 128 bits 


0b604a81 eca89e09 0b604a81 eca89e09 


OPc 


a64a507a ela2a98b b88eb421 0135dc87 


Value after 1^' encryption 


db2944cc e8e683cd 03fffl99 31al2135 


(SQN,AMF) XOR OPc, rotated 


b3eefea0 ed9d428e ad2alafb 0d0a3782 


Input to 2™ encryption 


68c7ba6c 057bcl43 aed5eb62 3cabl6b7 


Output of 2™ encryption 


d2efd25a 2a0ae5c2 14a2736b 97b2c4bO 


Value of f1 


74a58220 cba84c49 


Value of «* 


ac2cc74a 96871837 



4.7 



Test Set 5 



K: 4abldebO 5ca6cebO 51fc98e7 7d026a84 

RAND: 74bOcd60 31alc833 9b2b6ce2 b8c4al86 

SQN: e880alb5 80b6 

AMF: 9f07 

OP: 2dl6c5cd Ifdf6b22 383584e3 bef2a8d8 
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SQN,AMF expanded to 128 bits 


e880alb5 80b69f07 e880alb5 80b69f07 


OPc 


dcf07cbd 51855290 b92a07a9 891e523e 


Value after 1^' encryption 


02bffada 7137c492 c00e8452 d8c76eaa 


(SQN,AMF) XOR OPc, rotated 


51aaa61c 09a8cd39 3470dd08 dl33cd97 


Input to 2™ encryption 


53155CC6 789f09ab f47e595a 09f4a33d 


Output of 2™ encryption 


9517f960 43e73c62 27af7eaa bfa56d9c 


Value of f1 


49e785dd 12626ef2 


Value of «* 


9e857903 36bb3fa2 



4.8 



Test Set 6 



K: 6c38all6 ac280c45 4f59332e e35c8c4f 

RAND: ee6466bc 96202c5a 557abbef f8babf63 

SQN: 414b9822 2181 

AMF: 4464 

OP: IbaOOala 7c6700ac 8c3ff3e9 6ad08725 



SQN,AMF expanded to 128 bits 


414b9822 21814464 414b9822 21814464 


OPc 


3803ef53 63b947c6 aaa225e5 8fae3934 


Value after 1^' encryption 


bdf226fe cf9ff996 Ie5c2621 b764efbl 


(SON, AMF) XOR OPc, rotated 


ebe9bdc7 ae2f7d50 79487771 423803a2 


Input to 2™ encryption 


561b9b39 61b084c6 67145150 f55cecl3 


Output of 2"'' encryption 


3f8930e7 eb9d5d91 2a864e68 8e2885c5 


Value of f1 


078adfb4 88241a57 


Value of «* 


80246b8d 0186bcfl 



Algorithms f2, /5and f3 



5.1 



Overview 



The test data sets presented here are for the algorithms /2,/5 and/5. No detailed data of the internal states of Rijndael 
are presented here as these are covered in chapter 3. 



5.2 



Format 



Each Test starts by showing the inputs K and RAND to the algorithms, followed by the configuration field OP. 

Thereafter five rows of data are shown: 

Row 1, denoted a, shows the value of OPc. 

Row 2, denoted b, shows the output of the first encryption after XORing the value OPc. 

Row 3, denoted c, shows the input of the second encryption. 

Row 4, denoted d, shows the output of the second encryption. 

Row 5, denoted e, shows the values of/2, /5 and/5. 

The value OPc in the first row should not be computed on but off the USIM. In the example code OPc is computed 
inside the functions, so it was included in the table. 
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5.3 



Test Set 1 



K: 465b5ce8 bl99b49f aa5fOa2e e238a6bc 
RAND: 23553cbe 9637a89d 218ae64d ae47bf35 
OP: cdc202d5 123e20f6 2b6d676a c72cb318 





f2 and f5 


f3 


a 


cd63cb71 954a9f4e 


48a5994e 37a02baf 


b 


534a4bb4 02734529 


f993acl0 Ob4dcdOd 


c 


534a4bb4 02734529 f993acl0 0b4dcd0c 


02734529 f993acl0 Ob4dcdOd 534a4bb6 


d 


670b5715 163a3350 ede7889b d41a7blO 


796862d2 50clb54b f35540c9 85bbd364 


e 


a54211d5 e3ba50bf aa689c64 8370 


b40ba9a3 C58b2a05 bbf0d987 b21bf8cb 



5.4 



Test Set 2 



K: 0396eb31 7b6dlc36 fl9clc84 cd6ffdl6 
RAND: c00d6031 03dcee52 C4478119 494202e8 
OP: ff53bade 17df5d4e 793073ce 9d7579fa 





f2 and f5 


f3 


a 


53C15671 C60a4b73 


Ic55b4a4 41c0bde2 


b 


535bc878 505c5e56 


ea44d2df feb95fc4 


c 


535bc878 505c5e56 ea44d2df feb95fc5 


505c5e56 ea44d2df feb95fc4 535bc87a 


d 


97b6d5e8 9978al0d cff39c49 d9469dl2 


0b05658e bc7ac9df c87196ab 6aa778b4 


e 


d3a628ed 988620f0 C4778399 5f72 


58c433ff 7a7082ac d424220f 2b67c556 



5.5 Test Set 3 

K: fec86ba6 eb707edO 8905757b Ibb44b8f 

RAND: 9f7c8d02 laccf4db 213ccff0 c7f71aSa 

OP: dbc59adc b6f9a0ef 735477b7 fadf8374 





f2 and f5 


f3 


a 


1006020f 0a478bf6 b699fl5c 062e42b3 


b 


4d9dcc8a 47ab24fb Ifa4d9eb e571223f 


c 


4d9dcc8a 47ab24fb Ifa4d9eb e571223e 


47ab24fb Ifa4d9eb e571223f 4d9dcc88 


d 


234e4fcd 192cdf7e 368835d0 0a0f0c61 


4dbbb926 5eaf783b 50fc411a llb4122b 


e 


8011c48c 0c214ed2 33484dc2 136b 


5dbdbb29 54e8f3cd e665b046 179a5098 



5.6 



Test Set 4 



K: 9e5944ae a94b8116 5c82fbf9 f32db751 
RAND: ce83dbc5 4ac0274a 157cl7f8 Od017bd6 
OP: 223014C5 806694C0 07caleee f57f004f 





f2 and f5 \ f3 


a 


a64a507a ela2a98b b88eb421 0135dc87 


b 


7d6314b6 09442a46 bb7145b8 3094fdb2 


c 


7d6314b6 09442a46 bb7145b8 3094fdb3 


09442a46 bb7145b8 3094fdb2 7d6314b4 


d 


56f390f0 318C0249 4beb7949 3decf211 


4449bdc9 76b7dd7e Ilc5b940 b923e8da 


e 


f365cd68 3cd92e96 f 0b9c08a d02e 


e203edb3 971574f5 a94b0d61 b816345d 



5.7 Test Set 5 

K: 4abldebO 5ca6cebO 51fc98e7 7d026a84 

RAND: 74bOcd60 31alc833 9b2b6ce2 b8c4al86 

OP: 2dl6c5cd Ifdf6b22 383584e3 bef2a8d8 
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f2 and f5 


f3 


a 


dcfOVcbd 51855290 


b92a07a9 891e523e 


b 


de4f8GG7 20b29G02 


792483fb 51d93c94 


c 


de4f8667 20b29602 792483fb 51d93c95 


20b29602 792483fb 51d93c94 de4f8665 


d 


edll66dd c09dl433 el4afbb2 472b4c40 


aaa70ad6 66b84ebl 81d9004a 578cl0c7 


e 


5860fclb ce351e7e 31ella60 9118 


7657766b 373dlc21 38f307e3 de9242f9 



5.8 Test Set 6 

K: 6c38all6 ac280c45 4f59332e e35c8c4f 

RAND: ee6466bc 96202c5a 557abbef f8babf63 

OP: IbaOOala 7c6700ac 8c3ff3e9 6ad08725 





f2 and f5 


f3 


a 


3803ef53 63b947c6 


aaa225e5 8fae3934 


b 


85flc9ad ac26be50 


b4fe03c4 38cad685 


c 


85flc9ad ac26be50 b4fe03c4 38cad684 


ac26be50 b4fe03c4 38cad685 85flc9af 


d 


7db319c9 d3d51ccb bc6a06da 8a0e951c 


078f9ad4 9d370ce5 9054534b 519e830f 


e 


16c8233f 05a0ac28 45b0f69a b06c 


3f8c7587 fe8e4b23 3af676ae de30ba3b 



Algorithms f4 and /5' 



6.1 



Overview 



The test data sets presented here are for the algorithms /4 and/5*. No detailed data of the internal states of Rijndael are 
presented here as these are covered in chapter 3. 



6.2 



Format 



Each Test starts by showing the inputs K and RAND to the algorithms, followed by the configuration field OP. 

Thereafter five rows of data are shown: 

Row 1, denoted a, shows the value of OPc. 

Row 2, denoted b, shows the output of the first encryption after XORing the value OPc. 

Row 3, denoted c, shows the input of the second encryption. 

Row 4, denoted d, shows the output of the second encryption. 

Row 5, denoted e, shows the values of/4 and/5* 

The value OPc in the first row should not be computed on but off the USIM. In the example code OPc is computed 
inside the functions, so it was included in the table. 



6.3 



Test Set 1 



K: 465b5ce8 bl99b49f aa5fOa2e e238a6bc 
RAND: 23553cbe 9637a89d 218ae64d ae47bf35 
OP: cdc202d5 123e20f6 2b6d676a c72cb318 





f4 


f5* 


a 


cd63cb71 954a9f4e 


48a5994e 37a02baf 


b 


534a4bb4 02734529 


f993acl0 0b4dcd0d 


c 


f993acl0 0b4dcd0d 534a4bb4 0273452d 


0b4dcd0d 534a4bb4 02734529 f993acl8 


d 


3a0a77a6 c44ed94a 5ad3eb3f 2bcdlfee 


887d409d 3171e7ae ble55195 635d0a6e 


e 


f769bcd7 51044604 12767271 Ic6d3441 


451e8bec a43b 
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6.4 



Test Set 2 



K: 0396eb31 7b6dlc3S fl9clc84 cd6ffdl6 
RAND: c00d6031 03dcee52 C4478119 494202e8 
OP: ff53bade 17df5d4e 793073ce 9d7579fa 





f4 


f5* 


a 


53C15671 C60a4b73 


Ic55b4a4 41c0bde2 


b 


535bc878 505c5e56 


ea44d2df feb95fc4 


c 


ea44d2df feb95fc4 535bc878 505c5e52 


feb95fc4 535bc878 505c5e56 ea44d2d7 


d 


72699788 ef7a61a8 2226302c f8357838 


63304f01 a7cb2601 408d9704 046ac887 


e 


21a8clf9 29702adb 3e738488 b9f5c5da 


30fll970 61cl 



6.5 



Test Set 3 



K: fec86ba6 eb707edO 8905757b Ibb44b8f 
RAND: 9f7c8d02 laccf4db 213ccff0 C7f71a6a 
OP: dbc59adc b6f9a0ef 735477b7 fadf8374 





f4 1 f5* 


a 


1006020f 0a478bf6 b699fl5c 062e42b3 


b 


4d9dcc8a 47ab24fb Ifa4d9eb e571223f 


c 


Ifa4d9eb e571223f 4d9dcc8a 47ab24ff 


e571223f 4d9dcc8a 47ab24fb Ifa4d9e3 


d 


49af2f34 4d2d8fb5 fee9a493 8e9c72c8 


ceaadf8b 86811f35 71465e88 8475bd38 


e 


59a92d3b 476a0443 487055cf 88b2307b 


deacdd84 8cc6 



6.6 



Test Set 4 



K: 9e5944ae a94b8116 5c82fbf9 f32db751 
RAND: ce83dbc5 4ac0274a 157cl7f8 Od017bd6 
OP: 223014C5 806694C0 07caleee f57f004f 





f4 1 f5* 


a 


a64a507a ela2a98b b88eb421 0135dc87 


b 


7d6314b6 09442a46 bb7145b8 3094fdb2 


c 


bb7145b8 3094fdb2 7d6314b6 09442a42 


3094fdb2 7d6314b6 09442a46 bb7145bO 


d 


aaOf74d7 0b62e84f 650db901 847al8ec 


c6cff816 8ecl6553 38d688d7 a64aae30 


e 


Oc4524ad eac041c4 dd830d20 854fc46b 


6085a86c 6f63 



6.7 Test Set 5 

K: 4abldebO 5ca6ceb0 51fc98e7 7d026a84 

RAND: 74bOcd60 31alc833 9b2b6ce2 b8c4al86 

OP: 2dl6c5cd Ifdf6b22 383584e3 bef2a8d8 





f4 


f5* 


a 


dcf07cbd 51855290 


b92a07a9 B91e523e 


b 


de4fBGG7 20b29G02 


7924B3fb 51d93c94 


c 


792483fb 51d93c94 de4f8667 20b29606 


51d93c94 de4f8667 20b29602 792483f3 


d 


cOb295dd 891edd39 260d4349 f992996d 


22d52958 Ib2c5255 c399f91e Ildff7d5 


e 


Ic42e960 d89b8fa9 9f2744eO 708ccb53 


fe2555e5 4aa9 



6.8 



Test Set 6 



K: 6c38all6 ac280c45 4f59332e e35c8c4f 
RAND: ee6466bc 96202c5a 557abbef f8babf63 
OP: IbaOOala 7c6700ac 8c3ff3e9 6ad08725 
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f4 


f5* 


a 


3803ef53 63b947c6 


aaa225e5 8fae3934 


b 


85flc9ad ac26be50 


b4fe03c4 38cad685 


c 


b4fe03c4 38cad685 85flc9ad ac26be54 


38cad685 85flc9ad ac26be50 b4fe03cc 


d 


9f458392 850be6f5 d7ebf653 el3bee80 


27502278 72aaldb7 919ffOc7 bOc849cf 


e 


a7466ccl e6b2al33 7d49d3b6 6e95d7b4 


If53cd2b 1113 
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Annex A (informative): 
Change history 



Change history 


TSGSA 

# 


Version 


CR 


Tdoc SA 


New 
Version 


Subject/Comment 


SP-10 


SAGE 
v1.0 


- 


SP-010630 


3.0.0 


Approved as Release 1 999 


SP-11 


3.0.0 




- 


4.0.0 


Updated to Release 4 


SP-16 


4.0.0 


- 


- 


5.0.0 


Updated to Release 5 


SP-26 


5.0.0 




- 


6.0.0 


Updated to Release 6 


SP-36 
SP-42 


6.0.0 
7.0.0 




- 


7.0.0 
8.0.0 


Updated to Release 7 
Updated to Release 8 
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